HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Managed Care of North America, Inc.
bd_d284c416d84338c3 · schema v1 · pii pii-v1
Full breach record for Managed Care of North America, Inc. →Managed Care of North America (MCNA) notified consumers of a data breach where a cybercriminal accessed systems between Feb 26 and Mar 7, 2023. Exposed data included names, SSNs, driver's licenses, health insurance info, and dental records. MCNA engaged forensic investigators, notified law enforcement, and offered 1-2 years of identity theft protection.
Vermont clock✗ VT AG >45 bday12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_85569ed740a38ff7California State AGfiled 2023-05-26Candidate
- bd_bd79d24c6d422b05Washington State AGfiled 2023-05-26Verified
- bd_c6deca26eef87932Montana State AGfiled 2023-05-26Verified
- bd_d1e6071fa4c9eb84Maine State AGfiled 2023-05-26Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-05-26-managed-care-north-america-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2023
- Raw hash
- ad194c42e0b20e67284eca55227753c1b3eacacd44614bf447948911f2c28dd0
Reporting entity
- Name
- Managed Care of North America, Inc.norm: managed care of north america
Victim entity
- Name
- Managed Care of North America, Inc.norm: managed care of north america
Incident
- Discovered
- Mar 6, 2023
- Materiality determined
- May 26, 2023
- Notification sent
- May 26, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- told the state Medicaid agency that this event may have involved your information
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(81 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.